Live data from Hacker News

FTX stored private keys to crypto assets in plaintext, without access controls

twitter.com

141–150 of 222 posts

Re: FTX stored private keys to crypto assets in plaintext, without access controls

#141

It is fantastic that a company operating with such horrific practices is dead. While we are at it, when can we fix similar issues below with mainstream financial systems that millions of people are still using? - Social security numbers are used as a secret for identification, despite being in plaintext and having so low entropy as to be guessable, and originally issued on a card literally saying "Not for Identificat…

> Every bank check lists the bank account number, which serves as the only information needed for a party to issue a request to withdraw money from that account.

A check is simply a contract -- a promissory note. Like any contract you wouldn't sign it with someone you didn't trust, right?

(Obviously that statement, while true, is risable these days. But I remember a Bogart film in which he was setting a debt at a casino so asked the owner for a check -- he filled in not only the amount but his name, address and bank).

All the info on your check is just printed there as a convenience to you, or at least used to be. Until ~20 years ago physical checks were still sent back to your bank where they would check the signature, which could take a while! I think since the 72 hour rule went into place (and sending checks physically no longer allowed) the format was set by regulation

Re: FTX stored private keys to crypto assets in plaintext, without access controls

#142

It is fantastic that a company operating with such horrific practices is dead. While we are at it, when can we fix similar issues below with mainstream financial systems that millions of people are still using? - Social security numbers are used as a secret for identification, despite being in plaintext and having so low entropy as to be guessable, and originally issued on a card literally saying "Not for Identificat…

> Credit card numbers are similarly a private number used as a public number, and printed on plaintext on the card. I have an Apple Card. The only text on the card is my name. I think a lot of bank cards are starting to do similar stuff. It isn't foolproof, though. Someone somehow was able to charge against the card, a couple of months ago.

The lack of identifying numbers causes no end of confusion when I travel with it too, especially in European countries that Apple haven't launched the card in yet.

It got so annoying on a recent trip, I just reverted to using another conventional credit card. The Apple Card is generally fine any time I use tap to pay from the phone, but the physical card simply isn't as reliable as some other cards I have that generally "always work" abroad. I've even had restaurant staff treat me very suspiciously over the blank card.

Its also an odd card in that the physical card itself has no tap-to-pay functions at all; of course Apple want you to use the iPhone it can't operate without to do this part instead. Again though, if I do have to hand over the card, in Europe people will of course try and tap it instead of a swipe and once again confusion reigns.

Oh and if a server drops the card, it makes the most irritatingly loud clang being a small metal object - I would happily go back to plastic for the card!

Re: FTX stored private keys to crypto assets in plaintext, without access controls

#143

Earlier quoted context omitted.

"Sufficiently advanced incompetence is indistinguishable from malice." I don't recall who said it, but it seems to fit.

Hanlon's razor is an adage or rule of thumb that states, "Never attribute to malice that which is adequately explained by stupidity."

Right. My comment is a reverse of that, expressed in a similar form to Clarke's Law that "Sufficiently advanced technology is indistinguishable from magic."

But I stole it. I didn't make it up.

Re: FTX stored private keys to crypto assets in plaintext, without access controls

#144

Would this fall under "fake it till you make it" or "move fast and break things"?

I think the general rule is "move fast and break things" unless you are handling money or healthcare. That said, some financial and health-tech firms do seem to fly by the seat of their pants.

Re: FTX stored private keys to crypto assets in plaintext, without access controls

#145
post #130

Earlier quoted context omitted.

> What makes it work is that, under the SEPA Direct Debit framework, the risk of fraud and insufficient funds is 100% on the party initiating the direct debit. It also helps that the accountholder has to allow each party that will debit money from their account. By default, those requests are denied. AFAIK, the US works the other way around.

> By default, those requests are denied. That's not the case in Germany, at least.

Banks don't need a SEPA mandate to allow a direct debit?

Re: FTX stored private keys to crypto assets in plaintext, without access controls

#146

Stupid & Evil are best friends - if you're looking for one, the other is often nearby. There's going to be a mix of incredibly stupid and incredibly crooked behavior all through this. It's not a surprise that this "genius" is a delusional, pathetic dolt who couldn't operate a frozen banana stand properly, much less a multi-million dollar company. It's also not a surprise that he truly thinks he's innocent on all char…

> who couldn't operate a frozen banana stand properly,

A lot of column inches are dedicated to making it seem that way; however, I have a sneaking suspicion that there's _always_ money in the banana stand.

Re: FTX stored private keys to crypto assets in plaintext, without access controls

#147

Stupid & Evil are best friends - if you're looking for one, the other is often nearby. There's going to be a mix of incredibly stupid and incredibly crooked behavior all through this. It's not a surprise that this "genius" is a delusional, pathetic dolt who couldn't operate a frozen banana stand properly, much less a multi-million dollar company. It's also not a surprise that he truly thinks he's innocent on all char…

This is why seeing people attempt to excuse behavior via Hanlon's Razor makes me fume.

For any entity with a sufficient amount of power, stupidity is indistinguishable from malice.

Re: FTX stored private keys to crypto assets in plaintext, without access controls

#148
post #130

Earlier quoted context omitted.

> By default, those requests are denied. That's not the case in Germany, at least.

Banks don't need a SEPA mandate to allow a direct debit?

The SEPA mandate is between the parties in the transaction. While banks require their existence, it is usually not shared with the banks involved.

Re: FTX stored private keys to crypto assets in plaintext, without access controls

#149
post #130

Earlier quoted context omitted.

> What makes it work is that, under the SEPA Direct Debit framework, the risk of fraud and insufficient funds is 100% on the party initiating the direct debit. It also helps that the accountholder has to allow each party that will debit money from their account. By default, those requests are denied. AFAIK, the US works the other way around.

> By default, those requests are denied. That's not the case in Germany, at least.

Do you mean that if I know a German bank account number I can just withdraw money for me?

Be right back, asking some German friends for their bank account numbers.

Jokes aside, you're probably wrong. There's NO way I can just pull money from their bank account just by knowing their bank account number.

Re: FTX stored private keys to crypto assets in plaintext, without access controls

#150

Earlier quoted context omitted.

> What makes it work is that, under the SEPA Direct Debit framework, the risk of fraud and insufficient funds is 100% on the party initiating the direct debit. It also helps that the accountholder has to allow each party that will debit money from their account. By default, those requests are denied. AFAIK, the US works the other way around.

> By default, those requests are denied. This depends on your bank, mine allows them by default.

Which European bank is it?
Post reply on HN